# List organization users

**GET** `/users`

Returns the authenticated organization's members. Creation and
deletion of users are managed through the Salfio dashboard's
invitation flow and are intentionally not exposed via the API.

Base URL: `https://api.salfio.com/v1`

Tags: `users`

## Authorization

| Option | Scheme | Type | Sent as | Scopes |
| --- | --- | --- | --- | --- |
| Option 1 | `bearerAuth` | `http` | `Authorization: Bearer <token>` | — |

## Responses

| Status | Description | Media type |
| --- | --- | --- |
| `200` | Users belonging to the caller's organization. | `application/json` |
| `401` | Missing or invalid bearer token. The message is intentionally opaque — do not rely on it to distinguish "missing" from "invalid". | `application/json` |
| `429` | Per-organization or per-endpoint rate limit exceeded. | `application/json` |

### Example response: 200 — Users belonging to the caller's organization.

```json
{
  "data": [
    {
      "createdAt": "2026-06-09T00:00:00Z",
      "email": "alice@acme.com",
      "firstName": "Alice",
      "id": "00000000-0000-0000-0000-000000000000",
      "imageUrl": "https://example.com",
      "lastName": "Morgan",
      "updatedAt": "2026-06-09T00:00:00Z"
    }
  ],
  "meta": {
    "cursor": "string",
    "hasMore": true
  }
}
```

### Example response: 401 — Missing or invalid bearer token. The message is intentionally opaque — do not rely on it to distinguish "missing" from "invalid".

```json
{
  "error": {
    "code": "unauthorized",
    "message": "Authentication required"
  }
}
```

### Example response: 429 — Per-organization or per-endpoint rate limit exceeded.

```json
{
  "error": {
    "code": "rate_limited",
    "details": {
      "retry_after_seconds": 30
    },
    "message": "Rate limit exceeded"
  }
}
```

## Related pages

- [activities](./tags/activities.md)
- [assignment-rules](./tags/assignment-rules.md)
- [Authenticated health check](./gethealth.md)
- [cards](./tags/cards.md)
- [clients](./tags/clients.md)
- [Create a client](./createclient.md)
- [Create a manual activity](./createactivity.md)
- [Create a note on a client](./createnote.md)
- [Delete a client](./deleteclient.md)
- [Delete or archive an activity](./deleteorarchiveactivity.md)

# Agent Instructions

This portal answers questions programmatically. To receive a synthesized,
source-cited answer instead of crawling page by page, append the `?ask=`
query parameter to any page URL on this site:

    /guides/quickstart?ask=how+do+I+authenticate

Optional parameters:

- `&goal=<what-you-are-trying-to-do>` steers the answer toward your
  objective (e.g. `&goal=write+a+python+client`).
- `&version=<label>` scopes the answer to a mounted version when the
  portal publishes more than one.

The response is `text/markdown`: the answer followed by a `# Sources` list
of the portal pages it was grounded in. Status codes are the contract:

- `200` — the answer; `402` — the portal owner’s plan or answer credits are
  exhausted (surface this to your operator; do NOT retry); `429` — you are
  rate-limited; back off for the `Retry-After` seconds; `503` — the answer
  lane is temporarily unavailable; fall back to crawling the `.md` pages.

For the full corpus map read `llms.txt` at the site root; for the tool
surface (search + page fetch as MCP tools) see `/mcp`.
